Are there any Django packages to create signed urls for Google Cloud Storage resources?

Viewed 948

I'm writing a fairly simply photo app using django-rest-framework for the API and django-storages for the storage engine. The front end is being written in Vue.js. I have the uploading part working, and now I'm trying to serve up the photos. As now seems obvious when the browser tries to load the images from GCS, I just get a bunch of 403 Forbidden errors. I did some reading up on this and it seems that the best practice in my case would be to generate signed urls that expire in some amount of time. I haven't been able to find a package for this, which is what I was hoping for. Short of that, it's not clear to me precisely how to do this in Django.

4 Answers

This is a working code in django 1.11 with python3.5.

import os
from google.oauth2 import service_account
from google.cloud import storage


class CloudStorageURLSigner(object):
    @staticmethod
    def get_video_signed_url(bucket_name, file_path):
        creds = service_account.Credentials.from_service_account_file(
            os.environ.get('GOOGLE_APPLICATION_CREDENTIALS')
        )
        bucket = storage.Client().get_bucket(bucket_name)
        blob = bucket.blob(file_path)
        signed_url = blob.generate_signed_url(
            method='PUT',
            expiration=1545367030, #epoch time
            content_type='audio/mpeg', #change_accordingly
            credentials=creds
        )
        return signed_url

Extending @Evan Zamir's answer, instead of reassigning client and bucket you can get them from Django's default_storage (this will save time since these are already available).

This is in settings.py

from datetime import timedelta
from google.oauth2 import service_account

GS_CREDENTIALS = service_account.Credentials.from_service_account_file('credentials.json')
DEFAULT_FILE_STORAGE = "storages.backends.gcloud.GoogleCloudStorage"
GS_BUCKET_NAME = "my-bucket"
GS_EXPIRATION = timedelta(seconds=60)

In serializers.py

from django.core.files.storage import default_storage
from google.cloud.storage import Blob
from rest_framework import serializers

class SignedURLField(serializers.FileField):
    def to_representation(self, value):
        try:
            blob = Blob(name=value.name, bucket=default_storage.bucket)
            signed_url = blob.generate_signed_url(expiration=default_storage.expiration)
            return signed_url
        except ValueError as e:
            print(e)
            return value

You can use this class in your serializer like this,

class MyModelSerializer(serializers.ModelSerializer):
    file = SignedURLField()

Note: Do not provide GS_DEFAULT_ACL = 'publicRead' if you want signed URLs as it creates public URLs (that do not expire)

Related